Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Kaseya | Product: Virtual System/Server Administrator (VSA) | Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-7961 · CISA Known Exploited Vulnerabilities
Vendor: Liferay | Product: Liferay Portal | Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-23874 · CISA Known Exploited Vulnerabilities
Vendor: McAfee | Product: McAfee Total Protection (MTP) | McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-22506 · CISA Known Exploited Vulnerabilities
Vendor: Micro Focus | Product: Micro Focus Access Manager | Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-22502 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-38647 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2016-0167 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0878 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Edge and Internet Explorer | Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-31955 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1647 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Defender | Microsoft Defender contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-33739 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2016-0185 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0683 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-17087 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-33742 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-31199 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Enhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-33771 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.